Blame

4f0301 Samuli Seppänen 2025-02-11 09:01:15 1
# Easy Windows Guide
2
4b7700 Samuli Seppänen 2025-03-27 13:58:18 3
This page contains a no-frills guide to getting OpenVPN up and running on a Windows server and client(s). For a more detailed understanding of setting up OpenVPN and its advanced features, see the [HOWTO page](/HOWTO).
4f0301 Samuli Seppänen 2025-02-11 09:01:15 4
5
## Downloading and Installing OpenVPN
6
3b97b9 Samuli Seppänen 2025-04-22 12:06:26 7
### Installing manually
8
4f0301 Samuli Seppänen 2025-02-11 09:01:15 9
1. Download the installer from [here](https://openvpn.net/index.php/open-source/downloads.html) and run it on the server computer. During the setup, make sure to check mark the component named "EasyRSA 2 Certificate Management Scripts".
10
2. Install OpenVPN on each client. (This step can be skipped for now and done at any convenient time)
11
3b97b9 Samuli Seppänen 2025-04-22 12:06:26 12
### Installing with Chocolatey
13
14
[Chocolatey](https://chocolatey.org/) is a package manager for Windows. To install Chocolatey follow the official setup instructions which at the time of writing this (April 2025) are:
15
16
```
17
Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://community.chocolatey.org/install.ps1'))
18
```
19
20
To install latest (stable) OpenVPN on Windows:
21
22
```
23
choco install --force -y openvpn --package-parameters="/Gui /GuiOnLogon /Service /TapDriver /DcoDriver /Documentation /OpenSSL /SampleConfig"
24
```
25
26
You can omit the --package-parameters option if you are fine with the defaults as most would be.
27
4f0301 Samuli Seppänen 2025-02-11 09:01:15 28
## Certificates and Keys
29
3b97b9 Samuli Seppänen 2025-04-22 12:06:26 30
You can generate a certificate authority (CA) for OpenVPN with [easy-rsa 3](https://github.com/OpenVPN/easy-rsa). The instructions below refer to the easy-rsa 2 ([here](https://github.com/OpenVPN/easy-rsa-old)), which has not been in active development in a long time. Therefore the steps given may or may not work on modern Windows systems.
31
32
You can and should, whenever possible, generate the CA on a separate system, not on the OpenVPN server.
33
4f0301 Samuli Seppänen 2025-02-11 09:01:15 34
### Preparatory Steps
35
36
1. Navigate to the C:\Program Files\OpenVPN\easy-rsa folder on an elevated command prompt:
37
- Open the start menu
38
- Type "cmd"
39
- Right-click on Command Prompt and choose "Run as Administrator"
40
- Navigate to the correct folder:
41
```
42
cd "C:\Program Files\OpenVPN\easy-rsa"
43
```
44
45
2. Initialize the OpenVPN configuration:
46
```
47
init-config
48
```
49
* NOTE: Only run init-config once, during installation.
50
51
3. Open the vars.bat file in a text editor:
52
```
53
notepad vars.bat
54
```
55
56
4. Edit the following lines in vars.bat, replacing "US", "CA," etc. with your company's information:
57
```
58
set KEY_COUNTRY=US
59
set KEY_PROVINCE=CA
60
set KEY_CITY=SanFrancisco
61
set KEY_ORG=OpenVPN
62
set KEY_EMAIL=mail@host.domain
63
```
64
65
5. Save the file and exit notepad.
66
67
6. Run the following commands:
68
```
69
vars
70
clean-all
71
```
72
73
### Building Certificates and Keys
74
75
1. The certificate authority (CA) certificate and key:
76
```
77
build-ca
78
```
79
* When prompted, enter your country, etc. These will have default values, which appear in brackets. For your "Common Name," a good choice is to pick a name to identify your company's Certificate Authority. For example, "OpenVPN-CA":
f4f1f8 Samuli Seppänen 2025-02-27 09:27:12 80
```
81
Country Name (2 letter code) [US]:
82
State or Province Name (full name) [CA]:
83
Locality Name (eg, city) [SanFrancisco]:
84
Organization Name (eg, company) [OpenVPN]:
85
Organizational Unit Name (eg, section) []:
86
Common Name (eg, your name or your server's hostname) []:OpenVPN-CA
87
Email Address [mail@host.domain]:
88
```
4f0301 Samuli Seppänen 2025-02-11 09:01:15 89
90
2. The server certificate and key:
91
```
92
build-key-server server
93
```
94
* When prompted, enter the "Common Name" as "server"
95
* When prompted to sign the certificate, enter "y"
96
* When prompted to commit, enter "y"
97
98
3. Client certificates and keys:
99
- For each client, choose a name to identify that computer, such as "mike-laptop" in this example.
100
```
101
build-key mike-laptop
102
```
103
* When prompted, enter the "Common Name" as the name you have chosen (e.g. "mike-laptop")
f4f1f8 Samuli Seppänen 2025-02-27 09:27:12 104
- Repeat this step for each client computer that will connect to the VPN.
4f0301 Samuli Seppänen 2025-02-11 09:01:15 105
106
4. Generate Diffie Hellman parameters (This is necessary to set up the encryption):
107
```
108
build-dh
109
```
110
111
5. Generate a shared-secret key (Required when using tls-auth):
112
```
113
"C:\Program Files\OpenVPN\bin\openvpn.exe" --genkey --secret "C:\Program Files\OpenVPN\easy-rsa\keys\ta.key"
114
```
115
116
## Configuration Files
117
118
The sample configuration files can be easily found using the start menu:
119
```
120
Start Menu -> All Programs -> OpenVPN -> OpenVPN Sample Configuration Files
121
```
122
123
### Server Config File
07a87b Samuli Seppänen 2025-04-22 12:12:22 124
125
Server configurations should go to *C:\Program Files\OpenVPN\config-auto* if you wish run OpenVPN as a system service. If you wish to run OpenVPN server on-demand with OpenVPN GUI or from a terminal then place the configuration files should go to *C:\Program Files\OpenVPN\config*. Make sure the config file uses correct paths for the certificates and keys.
126
4f0301 Samuli Seppänen 2025-02-11 09:01:15 127
1. Copy the sample server configuration file to the easy-rsa folder:
128
```
129
copy "C:\Program Files\OpenVPN\sample-config\server.ovpn" "C:\Program Files\OpenVPN\easy-rsa\keys\server.ovpn"
130
```
131
132
2. Edit server.ovpn:
133
```
134
notepad "C:\Program Files\OpenVPN\easy-rsa\keys\server.ovpn"
135
```
136
137
3. Find and edit the following lines:
138
```
139
ca ca.crt
140
cert server.crt
141
key server.key
142
dh dh2048.pem
143
```
f4f1f8 Samuli Seppänen 2025-02-27 09:27:12 144
145
4. Edit them as follows:
146
4f0301 Samuli Seppänen 2025-02-11 09:01:15 147
```
148
ca "C:\\Program Files\\OpenVPN\\config\\ca.crt"
149
cert "C:\\Program Files\\OpenVPN\\config\\server.crt"
150
key "C:\\Program Files\\OpenVPN\\config\\server.key"
151
dh "C:\\Program Files\\OpenVPN\\config\\dh2048.pem"
152
```
153
154
4. Save and close
155
156
### Client Config Files
07a87b Samuli Seppänen 2025-04-22 12:12:22 157
158
Client configurations should usually go to *C:\Program Files\OpenVPN\config*. If you want, you can run client configurations as system services as well, in which case put them to *config-auto* directory instead. Also make sure the config file uses correct paths for the certificates and keys. Client configurations are similar to server configurations:
4f0301 Samuli Seppänen 2025-02-11 09:01:15 159
160
1. Copy the sample server configuration file to the easy-rsa folder with client's Common Name as the file name (each client will have a different file name):
161
```
162
copy "C:\Program Files\OpenVPN\sample-config\client.ovpn" "C:\Program Files\OpenVPN\easy-rsa\keys\mike-laptop.ovpn"
163
```
164
165
2. Edit client's config file:
166
```
167
notepad "C:\Program Files\OpenVPN\easy-rsa\keys\mike-laptop.ovpn"
168
```
169
170
3. Find and edit the following lines:
171
```
172
ca ca.crt
173
cert client.crt
174
key client.key
175
```
f4f1f8 Samuli Seppänen 2025-02-27 09:27:12 176
4. Edit them as follows:
177
4f0301 Samuli Seppänen 2025-02-11 09:01:15 178
```
179
ca "C:\\Program Files\\OpenVPN\\config\\ca.crt"
180
cert "C:\\Program Files\\OpenVPN\\config\\mike-laptop.crt"
181
key "C:\\Program Files\\OpenVPN\\config\\mike-laptop.key"
182
```
183
184
4. Edit the following line, replacing "my-server-1" with your server's public Internet IP Address or Domain Name:
185
```
186
remote my-server-1 1194
187
```
188
189
5. Save and close
190
8cdac5 Samuli Seppänen 2025-04-30 07:41:10 191
## Enable IP forwarding on OpenVPN server
192
193
You need to enable IP forwarding on the server:
194
195
```
196
Set-NetIPInterface -Forwarding Enabled
197
```
198
199
Without this you cannot access any hosts behind the VPN server.
200
cab30a Samuli Seppänen 2025-05-30 07:06:55 201
## Enable packet forwarding on the Cloud provider
202
203
Some Cloud providers drop IP packets where the source or destination does not match the virtual machine's network interface. In practice this prevents forwarding traffic to subnets behind the OpenVPN server. In AWS this is called [Source/Destination check](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html) and on an OpenVPN server (or client with iroutes) you need to disable it.
204
07a87b Samuli Seppänen 2025-04-22 12:12:22 205
## Starting OpenVPN
4f0301 Samuli Seppänen 2025-02-11 09:01:15 206
07a87b Samuli Seppänen 2025-04-22 12:12:22 207
On the server we recommend running OpenVPN as a system service:
4f0301 Samuli Seppänen 2025-02-11 09:01:15 208
07a87b Samuli Seppänen 2025-04-22 12:12:22 209
```
210
Set-Service -Name OpenVPNService -StartupType automatic
211
Start-Service OpenVPNService
212
```
4f0301 Samuli Seppänen 2025-02-11 09:01:15 213
07a87b Samuli Seppänen 2025-04-22 12:12:22 214
On clients you may want to use OpenVPN GUI instead:
4f0301 Samuli Seppänen 2025-02-11 09:01:15 215
07a87b Samuli Seppänen 2025-04-22 12:12:22 216
1. On client run OpenVPN GUI from:
4f0301 Samuli Seppänen 2025-02-11 09:01:15 217
```
218
Start Menu -> All Programs -> OpenVPN -> OpenVPN GUI
219
```
220
2. Double click the icon which shows up in the system tray to initiate the connection. The resulting dialog should close upon a successful start.
3b97b9 Samuli Seppänen 2025-04-22 12:06:26 221
3. If you have multiple OpenVPN configurations available you can pick which one to use by right-clicking on the system tray icon.
4f0301 Samuli Seppänen 2025-02-11 09:01:15 222
223
## Further Considerations / Troubleshooting
224
225
### Firewall Configuration
6dc85d Samuli Seppänen 2025-04-30 08:46:29 226
227
If you have connection problems, make sure to set a rule on your server's firewall allowing incoming traffic on UDP port 1194. You can do this from the Windows Firewall application. You may also need to move the Windows Data Channel Offload (or TAP-Windows6) interface in the public firewall zone.
228
229
If you prefer Powershell then use:
230
231
```
232
Set-NetConnectionProfile -Name "OpenVPN Data Channel Offload" -NetworkCategory Public
233
New-NetFirewallRule -DisplayName "Inbound OpenVPN UDP 1194" -Profile @('Private', 'Public') -Direction Inbound -Protocol UDP -LocalPort @('1194') -Action allow
234
```
235
236
To verify that the new rule was created:
237
238
```
239
Get-NetFirewallRule -All|where-object { $_.DisplayName -eq "Inbound OpenVPN UDP 1194" }
240
```
4f0301 Samuli Seppänen 2025-02-11 09:01:15 241
242
### Port Forwarding
243
244
If your server is behind a router, you will need to forward the port chosen for OpenVPN (in this example UDP 1194) to the server. Consult your router's documentation for details on this.
245
246
To set up port forwarding, you will likely need to set up the server with a static local IP address instead of the default dynamic (changing) IP. Instructions for Windows XP may be found [here](http://www.ehow.com/how_4393725_static-ip-address-win-xp.html). Make sure to choose a static IP address that is not in the range your router might assign as a dynamic IP, but is within the router's subnet (usually 192.168.0.xxx, 10.0.0.xxx, or similar).
247
248
### Static Internet IP
249
512553 Samuli Seppänen 2025-05-30 06:49:53 250
Your server will need to have a static public internet IP or Domain Name to be accessible over the long term. For IPv6 addresses this is typically not a problem, but due to scarcity of IPv4 addresses you need to pay extra for those - especially static, public ones. Each Cloud provider has their own terminology for these static public IPs. For example AWS calls the "Elastic IPs" whereas Hetzner Cloud calls them "Floating IPs". In any case you your VPN clients don't have universal IPv6 connectivity (which is likely), you need one.
251
252
Another solution is to sign up for an account with DynDNS and install the DynDNS Updater on your server. When signing up you will determine the static Domain Name of your server. (For example, "myserver.dyndns.org") You will use this Domain Name in the client configuration files as part of the "remote" directive.
4f0301 Samuli Seppänen 2025-02-11 09:01:15 253
254
### Running OpenVPN as a Service
512553 Samuli Seppänen 2025-05-30 06:49:53 255
4f0301 Samuli Seppänen 2025-02-11 09:01:15 256
Running OpenVPN as a service will allow:
257
258
a. OpenVPN to be run from a non-administrator account.
259
260
b. OpenVPN to be started automatically on system startup. This is often preferred on the server machine, as well as any machines which will be constantly connected to the server.
261
512553 Samuli Seppänen 2025-05-30 06:49:53 262
#### Enabling OpenVPN service using services.msc
263
4f0301 Samuli Seppänen 2025-02-11 09:01:15 264
1. Run the Windows Service administrative tool:
265
- Press Windows Key + R
266
- Type "services.msc" and press Enter.
267
```
268
services.msc
269
```
270
271
2. Find the OpenVPN service, and set its Startup Type to "automatic."
272
273
3. Optionally, start the service now.
274
512553 Samuli Seppänen 2025-05-30 06:49:53 275
#### Enabling OpenVPN service using Powershell
276
277
To enable and start the OpenVPN service with Powershell:
278
279
```
280
Set-Service -Name OpenVPNService -StartupType automatic
281
Start-Service OpenVPNService
282
```
283
4f0301 Samuli Seppänen 2025-02-11 09:01:15 284
### Security Tips
285
286
1. Transmit all needed files to the client computers using a secure means such as a USB drive (email is not always a secure means).
287
2. Choose a port other than UDP 1194, and replace the port number wherever this guide mentions UDP port 1194.
288
289
### Cloning OpenVPN Servers
290
291
If including OpenVPN in a cloned server build you will find that all servers will have the same MAC address for the TAP device. This will cause packet loss across the network. Standard methods of changing the IP address from scripts do not work on the TAP device, to resolve this delete and recreate the TAP device using the scripts included with OpenVPN:
292
293
```
294
C:\Program Files\OpenVPN\bin\deltapall
295
C:\Program Files\OpenVPN\bin\addtap
296
```
297
298
You will then have to rename the connection to match the entry in the config file.